Security News

Breach at Polish Invoicing Platform Fakturownia Exposes Customer and Partner Data

The Record · 1 Oct 2026
Key Takeaway Businesses that rely on third-party invoicing or accounting platforms should ask vendors about their security practices and monitor for unusual account activity following any reported breach.

Fakturownia, a widely used online invoicing platform in Poland, has confirmed that an attacker exploited a vulnerability in its systems to gain unauthorized access to its servers. The company is still working to determine the full scope of affected customers, but says compromised data may include user and company account information, password hashes, bank account details, authentication and integration tokens, and data belonging to customers and business partners. Invoices issued before 2023 may also have been accessed, though payment card data was not affected.

The incident has drawn added attention because Fakturownia integrates with Poland's National e-Invoicing System (KSeF), a government tax platform many businesses must use. Both the Finance Ministry and Fakturownia say a review found no evidence that KSeF itself was breached or that digital certificates used to access it were compromised. Fakturownia says it detected the unauthorized access, blocked the attacker, rotated passwords and application keys, and moved operations to new servers while working with external cybersecurity specialists and notifying Polish authorities.

A hacker using the alias 'Fingerprint' has claimed to have stolen six terabytes of invoice data and provided screenshots to a Polish security outlet, though this claim has not been independently verified. Polish officials say they are investigating and have vowed consequences for those responsible.

Primary source podatki.gov.pl ->
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.